New Delhi: Bank of Baroda has come under the spotlight following claims by a hacking group that it has leaked nearly 1TB (1,000GB) of sensitive customer and internal banking data on the dark web. The alleged incident has drawn significant attention from cybersecurity researchers and threat intelligence platforms. However, Bank of Baroda has not officially confirmed that any data breach has occurred, and no government agency has so far verified the authenticity of the claims.
According to reports, the hacking group TripleX has claimed responsibility for the alleged leak. The group’s claims surfaced through a listing on the dark web monitoring platform Ransomware.live dated July 24, where the attackers alleged that they had published a large volume of confidential banking information online.
As per the claims, the leaked dataset allegedly contains between 100,000 and 300,000 customer application formssubmitted during the account opening process. The documents are said to include customer photographs and identity verification records.
The hackers further alleged that the exposed information includes Aadhaar details, savings and current account information, loan application records, NetBanking user details, as well as documents related to NRI banking and corporate banking services. If verified, the alleged exposure could potentially involve highly sensitive personal and financial information belonging to Bank of Baroda customers.
At present, there is no official confirmation from the bank regarding the authenticity of the claims or whether any customer information has actually been compromised. Similarly, government authorities and cybersecurity agencies have not announced any findings confirming that a breach has taken place. As a result, the alleged data leak remains unverified.
Cybersecurity experts note that claims posted by ransomware groups on dark web forums should be treated with caution until independently verified. Such groups sometimes publish genuine stolen data, while in other instances they may exaggerate or make unverified claims to pressure organisations or gain publicity.
Experts also advise customers not to panic but to remain vigilant. As a precaution, users should regularly monitor their bank accounts for any unauthorised transactions, avoid responding to unsolicited calls or messages seeking banking credentials, enable multi-factor authentication wherever available, and never share passwords, OTPs or PINs with anyone.
If the alleged breach is confirmed through official investigation, it could raise significant concerns regarding data protection, customer privacy, and cybersecurity within India’s banking sector. Investigations by the bank and relevant authorities are expected to determine the authenticity of the claims, assess the extent of any potential exposure, and recommend appropriate remedial measures if required.
